# vex

Published articles for vex.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Going deep: Upstream distros and hidden CVEs

DevFeed: [Going deep: Upstream distros and hidden CVEs](<https://devfeed.tech/articles/going-deep-upstream-distros-and-hidden-cves-13069.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/going-deep-upstream-distros-and-hidden-cves>)

Published: 2026-02-25T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [Docker](<https://devfeed.tech/topics/docker.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [debian](<https://devfeed.tech/tags/debian.md>), [debian-containers](<https://devfeed.tech/tags/debian-containers.md>), [dhi](<https://devfeed.tech/tags/dhi.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-containers](<https://devfeed.tech/tags/docker-containers.md>), [docker-hardened-images](<https://devfeed.tech/tags/docker-hardened-images.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article argues that container vendors relying on upstream distributions such as Debian or Alpine can inherit vulnerabilities because fixes may lag between upstream availability and downstream image releases. It examines Docker Hardened Images and claims that some CVEs are suppressed through no-DSA classifications and VEX documents even when fixes exist upstream but have not been incorporated into the images.

### Source excerpt

Are all zero-CVE images truly secure? A deep dive into Debian no-DSA, VEX suppression, and why transparency matters in container supply chain security.

## Grype Adds OpenVEX Support for Vulnerability Analysis

DevFeed: [Grype Adds OpenVEX Support for Vulnerability Analysis](<https://devfeed.tech/articles/vexed-then-grype-about-it-chainguard-and-anchore-announce-grype-supports-openvex-13311.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/vexed-then-grype-about-it-chainguard-and-anchore-announce-grype-supports-openvex>)

Published: 2023-10-10T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [grype](<https://devfeed.tech/topics/grype.md>), [openvex](<https://devfeed.tech/topics/openvex.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity-and-infrastructure-security-agency](<https://devfeed.tech/tags/cybersecurity-and-infrastructure-security-agency.md>), [grype](<https://devfeed.tech/tags/grype.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>)

### AI overview

Grype, Anchore's open-source vulnerability scanner, now supports OpenVEX, a machine-readable standard for vulnerability analysis. The article explains how this can provide context for vulnerabilities and help reduce false positives and vulnerability-management effort.

### Source excerpt

Open source vulnerability scanner Grype has added support for OpenVEX, making software supply chain security easier. Learn how to implement it today.

## Why Chainguard uses Grype as its first line of defense for CVEs

DevFeed: [Why Chainguard uses Grype as its first line of defense for CVEs](<https://devfeed.tech/articles/why-chainguard-uses-grype-as-its-first-line-of-defense-for-cves-13327.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-chainguard-uses-grype-as-its-first-line-of-defense-for-cves>)

Published: 2023-10-06T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Go](<https://devfeed.tech/topics/go.md>), [trivy](<https://devfeed.tech/topics/trivy.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [false-negative](<https://devfeed.tech/tags/false-negative.md>), [false-positive](<https://devfeed.tech/tags/false-positive.md>), [go](<https://devfeed.tech/tags/go.md>), [grype](<https://devfeed.tech/tags/grype.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [prisma-cloud](<https://devfeed.tech/tags/prisma-cloud.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vex](<https://devfeed.tech/tags/vex.md>)

### AI overview

Chainguard explains why it selected Grype as the foundation of its internal vulnerability detection system. The article describes scanning early in the software delivery pipeline, using Grype as a Go library to scan Wolfi APK packages before container images are built, and contributing vulnerability data and improvements to the open-source project. It also briefly compares Grype's open data pipeline with Trivy's.

### Source excerpt

Chainguard harnesses Grype's open-source power to ensure minimal CVEs in images, prioritizing user security.

## Working with government and industry to put open source security tooling into practice

DevFeed: [Working with government and industry to put open source security tooling into practice](<https://devfeed.tech/articles/working-with-government-and-industry-to-put-open-source-security-tooling-into-practice-13342.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/working-with-government-and-industry-to-put-open-source-security-tooling-into-practice>)

Published: 2023-09-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>)

Tags: [bombshell](<https://devfeed.tech/tags/bombshell.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [protobom](<https://devfeed.tech/tags/protobom.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [vex](<https://devfeed.tech/tags/vex.md>)

### AI overview

Chainguard describes two open-source SBOM tools developed with the U.S. Department of Homeland Security and other startups: protobom, which translates SBOM data between formats, and bomshell, which combines and composes SBOMs. The initiative aims to improve software supply chain security and visibility.

### Source excerpt

Pioneering SBOM tools with government and industry allies, Chainguard advances open source security measures.

## Celebrating 5 years of NTIA's SBOM work

DevFeed: [Celebrating 5 years of NTIA's SBOM work](<https://devfeed.tech/articles/celebrating-5-years-of-ntia-s-sbom-work-12919.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/celebrating-5-years-of-ntias-sbom-work>)

Published: 2023-06-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [distroless](<https://devfeed.tech/topics/distroless.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-dark-matter](<https://devfeed.tech/tags/software-dark-matter.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [sofware-supply-chain](<https://devfeed.tech/tags/sofware-supply-chain.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

The article commemorates five years of the NTIA's Software Bill of Materials work and reviews the development of SBOMs as a foundation of software supply chain security. It describes the NTIA's initiative, its multi-stakeholder guidelines, and CISA's continuing role in advancing software transparency.

### Source excerpt

Celebrate 5 transformative years of SBOM work with Chainguard, reflecting on the journey of software bill of materials.

## Chainguard to accelerate VEX adoption through OpenVEX specification

DevFeed: [Chainguard to accelerate VEX adoption through OpenVEX specification](<https://devfeed.tech/articles/chainguard-to-accelerate-vex-adoption-through-openvex-specification-12985.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-to-accelerate-vex-adoption-through-openvex-specification>)

Published: 2023-01-31T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [openvex](<https://devfeed.tech/topics/openvex.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [google](<https://devfeed.tech/tags/google.md>), [images](<https://devfeed.tech/tags/images.md>), [linux-foundation](<https://devfeed.tech/tags/linux-foundation.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [sbom-vex](<https://devfeed.tech/tags/sbom-vex.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-tool](<https://devfeed.tech/tags/vulnerability-tool.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard announces the OpenVEX specification and reference toolchain, developed with industry and CISA VEX Working Group collaboration. OpenVEX helps software producers describe vulnerability exploitability and enables consumers to filter false positives, complementing SBOMs.

### Source excerpt

VEX needs the industry to come together to build formats that integrate into existing practices. OpenVEX enables organizations to put VEX into practice.